[dundee] Forensic Computing

tlug at defcon1.eu tlug at defcon1.eu
Sun Nov 22 14:03:30 UTC 2009


Did you check deleted files first and did you run any  carving tool? Maybe you will find any useful info within deleted files. 
------Original Message------
From: Axel
Sender: dundee-bounces at lists.lug.org.uk
To: dundee at lists.lug.org.uk
ReplyTo: Tayside Linux User Group
Subject: [dundee] Forensic Computing
Sent: 22 Nov 2009 13:44


Hey,

one problem I have solve. The FTK-Imager can convert the image to a dd  
image. So it's possible to mount this without any trouble at Linux.

Now, there is an another problem. There are to Word files  
Burinator1.doc and Burinator2.doc. This files protected with a  
password. Advise the password was without success and I cannot find  
the password in the image. Everyone know if the password available in  
the image?

A brute force attack is already started, but this need a couple of days.

Cheers
Axel



_______________________________________________
dundee GNU/Linux Users Group mailing list
dundee at lists.lug.org.uk  http://dundeelug.org.uk
https://mailman.lug.org.uk/mailman/listinfo/dundee
Chat on IRC, #tlug on irc.lug.org.uk


------------------


More information about the dundee mailing list